GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,383
Erlang
33
GitHub Actions
22
Go
2,141
Maven
5,000+
npm
3,803
NuGet
687
pip
3,479
Pub
12
RubyGems
897
Rust
898
Swift
38
Unreviewed advisories
All unreviewed
5,000+
165 advisories
Filter by severity
Authentication Bypass by Spoofing vulnerability in webtechideas WTI Like Post allows...
Moderate
Unreviewed
CVE-2024-33917
was published
May 17, 2024
Authentication Bypass by Spoofing vulnerability in LionScripts IP Blocker Lite allows...
Moderate
Unreviewed
CVE-2024-30479
was published
May 17, 2024
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This...
Moderate
Unreviewed
CVE-2023-50224
was published
May 3, 2024
TP-Link TL-WR902AC loginFs Improper Authentication Information Disclosure Vulnerability. This...
Moderate
Unreviewed
CVE-2023-44447
was published
May 3, 2024
A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748...
Moderate
Unreviewed
CVE-2024-30190
was published
Apr 9, 2024
A vulnerability has been identified in SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0) (All versions),...
Moderate
Unreviewed
CVE-2024-30189
was published
Apr 9, 2024
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to...
Moderate
Unreviewed
CVE-2021-22890
was published
May 24, 2022
An authentication bypass by spoofing of a device with a synthetic IP address is possible in...
Moderate
Unreviewed
CVE-2023-28803
was published
Oct 23, 2023
This Activity Log WordPress plugin before 2.8.8 retrieves client IP addresses from potentially...
Moderate
Unreviewed
CVE-2023-4281
was published
Sep 25, 2023
The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to...
Moderate
Unreviewed
CVE-2023-4631
was published
Sep 25, 2023
The User Access Manager WordPress plugin before 2.2.18 prioritizes getting a visitor's IP from...
Moderate
Unreviewed
CVE-2022-1601
was published
Aug 30, 2023
The foundry campaigns service was found to be vulnerable to an unauthenticated information...
Moderate
Unreviewed
CVE-2023-30950
was published
Aug 4, 2023
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this...
Moderate
Unreviewed
CVE-2023-34167
was published
Jun 19, 2023
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this...
Moderate
Unreviewed
CVE-2023-34160
was published
Jun 19, 2023
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this...
Moderate
Unreviewed
CVE-2023-34158
was published
Jun 19, 2023
There is a traffic hijacking vulnerability in Huawei routers. Successful exploitation of this...
Moderate
Unreviewed
CVE-2022-48469
was published
Jun 16, 2023
Legacy pairing and secure-connections pairing authentication in Bluetooth® BR/EDR Core...
Moderate
Unreviewed
CVE-2020-10135
was published
May 24, 2022
The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential...
Moderate
Unreviewed
CVE-2019-18659
was published
May 24, 2022
Cache Poisoning issue exists in DNS Response Rate Limiting.
Moderate
Unreviewed
CVE-2013-5661
was published
May 5, 2022
In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in...
Moderate
Unreviewed
CVE-2024-28228
was published
Mar 7, 2024
Authentication Bypass by Spoofing in github.com/greenpau/caddy-security
Moderate
CVE-2024-21494
was published
for
github.com/greenpau/caddy-security
(Go)
Feb 17, 2024
An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a...
Moderate
Unreviewed
CVE-2023-4001
was published
Jan 15, 2024
Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows...
Moderate
Unreviewed
CVE-2023-7169
was published
Feb 8, 2024
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2....
Moderate
Unreviewed
CVE-2021-32076
was published
May 24, 2022
ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and...
Moderate
Unreviewed
CVE-2024-0454
was published
Jan 12, 2024
ProTip!
Advisories are also available from the
GraphQL API